Nova security group not working properly

I have a multi-node Openstack Grizzly setup: 1 front-end network node (3 nics) and 2 compute nodes (3 nics). Everything seems to work perfectly: VM's have external access, I can ping the VM's from the virtual router, VM's can communicate between themselves...

However, I am unable to ping the VM's from any compute node to the VM's. I have added the virtual router to the routing table, I changed the default security permissions... so I think that it is a problem with grizzly's security group filtering.

I tried executing tcpdump in VM's eth0 and also in its counterpart in br-int (qvoc55...) and sending a ping. The icmp package arrives at br-int -> qvoc55... but not to VM's eth0, so it is being filtered by nova security policies. Somehow, the Accept all policies are being ignored by nova, what can I do then?